CVE-2022-42331

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/03/2023
Last modified:
04/02/2024

Description

x86: speculative vulnerability in 32bit SYSCALL path Due to an oversight in the very original Spectre/Meltdown security work (XSA-254), one entrypath performs its speculation-safety actions too late. In some configurations, there is an unprotected RET instruction which can be attacked with a variety of speculative attacks.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:xen:xen:*:*:*:*:*:*:x86:* 4.5.0 (including) 4.17.0 (including)
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*